CVE-2025-40801

8.1

Siemens · COMOS, NX, Simcenter, and Tecnomatix Plant Simulation

A vulnerability in the SALT SDK causes improper TLS certificate validation, potentially allowing attackers to conduct man-in-the-middle attacks on affected Siemens software products.

Executive summary

A critical vulnerability in the Siemens SALT SDK leaves multiple engineering and simulation products susceptible to man-in-the-middle attacks due to improper TLS certificate validation.

Vulnerability

The SALT SDK fails to perform necessary server certificate validation when establishing TLS connections to the authorization server, which allows an unauthenticated attacker to intercept or manipulate traffic.

Business impact

The vulnerability carries a CVSS score of 8.1, indicating a high severity risk. Successful exploitation allows an attacker to perform man-in-the-middle attacks, potentially leading to the interception of sensitive authorization data, unauthorized access, or the compromise of engineering workflows, which could result in significant operational disruption or intellectual property theft.

Remediation

Immediate Action: Update all affected Siemens software to the versions specified in the vendor security advisory (SSA-710408) to resolve the missing certificate validation logic.

Proactive Monitoring: Monitor network traffic for anomalous TLS handshake failures or unauthorized attempts to access internal authorization servers, particularly from untrusted network segments.

Compensating Controls: Ensure that affected systems are isolated within trusted network zones and utilize VPNs or encrypted tunnels to restrict the attack surface for communication with external services.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the critical nature of the affected engineering software, organizations must prioritize patching these systems. Administrators should reference the provided Siemens security portal links to identify the exact build versions required for their specific environment and initiate deployment immediately to prevent potential interception of authorization credentials.

More Siemens CVEs

Sources